Android forensics
by - Thursday, January 1, 1970 at 12:00 AM
A friend wants me to check his android for evidence that might get him in trouble if his phone was checked by his parents. Apparently his dad is an expert. He wants to be sure that there are no traces of camera activity on a specific date.
I checked logs with android studio and could not see anything before the last reboot, but, I am no forensic expert.
Do you know if apps store any data anywhere else on the phone? if yes, how do I access it and delete/tamper with it?
Thank you!
Reply
Use the software from Cellebrite, somewhere in the public there is it)
Reply
Is there any less costly software specific to data extraction? Cellebrite is overkill for what I need.
Reply
You need a little more info.. What kind of phone, OS version, do you have root privilege?

Assuming it's a relatively new phone, your Android backup could be quite limited and you may need root or another exploit to dump the file system. A place to start though is use ADB to take a full backup, then analyze that backup to see how much the phone was willing to give up.

There are artifacts stored even when the original picture is deleted. Thumbnail cache, gallery cache, etc. The quickest way is to dump the file system and run it through something free like Autopsy, timeline it down to when your friend thinks the pictures were taken and see what other kinds of files were generated around that time.

Alternatively, what NFU02 is referring to is that there may or may not be some cracked versions of certain software floating around that you can get your hands on if you dig.
Reply


 Users viewing this thread: Android forensics: No users currently viewing.